LIGHTHOUSE

KKM AI CONCIERGE

Privacy Policy

How KK-Apartamenty processes personal data when Lighthouse supports guest conversations and booking enquiries.

Last updated: 8 August 2026

1. Controller and scope

The controller of personal data processed in Lighthouse is:

KK-Apartamenty sp. z o.o.
ul. Śląska 57
66-400 Gorzów Wielkopolski
Poland

Lighthouse is a communication and AI concierge system used to answer guest enquiries, support stays, and assist with booking-related communication through Web Chat, Facebook Messenger and other enabled channels.

2. Data we process

Depending on the channel and the information you choose to provide, we may process:

  • Meta/Facebook Page, Messenger user and conversation identifiers needed to route messages;
  • the content, language, timestamps and delivery status of messages;
  • contact details and booking information you voluntarily provide, such as name, phone number, email address, stay dates, number of guests and special requests;
  • technical records needed for security, webhook deduplication, system health, error investigation and audit;
  • conversation state, AI interpretation results, verified source references and human escalation records.

We do not ask you to send payment card credentials, passwords or access tokens through a conversation.

3. Purposes and legal bases

We process data to answer enquiries, verify availability and approved business information, prepare quotations, support booking and transfer requests, provide pre-stay or in-stay assistance, maintain conversation continuity, prevent duplicate or abusive requests, secure the service and meet legal obligations. Depending on the circumstances, the legal basis is taking steps at your request before a contract or performing a contract, our legitimate interests in providing secure customer service, compliance with a legal obligation, or consent where specifically requested.

4. AI-assisted processing and human review

Lighthouse uses AI to understand natural-language messages, maintain structured conversation context and compose responses. Availability, prices and property rules are intended to come from verified business engines or approved knowledge, rather than being invented by the AI. Requests may be escalated to an authorised human operator where confirmation or individual judgement is required. Lighthouse does not make decisions producing legal or similarly significant effects solely by automated means.

5. Service providers and disclosures

We use only providers needed to operate the service:

  • Vercel — application hosting and server-side execution.
  • Neon — managed PostgreSQL database hosting.
  • OpenAI — AI-assisted language understanding and response composition through the API.
  • Meta Platforms — Facebook Page and Messenger channel delivery.

These providers process data under their applicable contracts and security terms. We may also disclose data where required by law or necessary to establish, exercise or defend legal claims.

6. International transfers

Some providers may process data outside the European Economic Area. Where required, transfers are covered by an adequacy decision, Standard Contractual Clauses or another lawful safeguard under applicable data-protection law. The precise processing location can depend on the provider configuration and service used.

7. Security and retention

We use access controls, server-side credentials, encrypted transport, restricted administrative access, secret redaction, and database-backed audit and deletion controls. No online service can guarantee absolute security.

Operational conversation data is normally retained for up to 365 days, Mission Recorder records for up to 365 days, and webhook deduplication identifiers for up to 30 days. Data may be deleted or anonymised earlier upon a valid request. A longer period may apply where necessary for accounting, legal claims, fraud prevention or another legal obligation.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting prior lawful processing. We may need limited information to verify your identity and locate the relevant conversation.

You may also lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO) in Poland.

9. Contact

Privacy requests may be sent in writing to the controller’s postal address shown above. Please provide only the minimum information needed to identify the relevant interaction. Instructions specifically for deletion are available on the Data Deletion page.

10. Changes

We may update this policy when the service, providers or legal requirements change. The current version and update date are published on this page.